Ransomware hits cities: how to protect yourself
In 2019 several cities in the United States went through something that seemed straight out of a movie: from one day to the next, their systems stopped responding. Procedures halted, emails locked, records hijacked, and a cold message demanding a ransom to return access. It wasn’t a single isolated case; it was a wave of ransomware attacks against municipalities that brought entire governments to their knees for days or weeks.
If a city hall with a budget and IT staff can fall like that, the uncomfortable question is obvious: what would happen to your company? The good news is that real defense doesn’t depend on having the most expensive software on the market, but on three orderly, measurable habits. At Normandia Web we see it often: the businesses that survive an attack aren’t the ones that spend the most, but the ones that have their data, processes, and history well protected and within reach.
What ransomware really is (and why it hits small businesses)
Ransomware is a type of malicious program that encrypts your files and demands a payment to release them. It usually gets in through the most ordinary things: an email with an attachment, a weak password, an unpatched system, or an infected USB drive. It doesn’t discriminate by company size; on the contrary, small businesses are often the easy target because they assume “it won’t happen to us.”
The damage isn’t just the ransom. It’s the halted operation, the customers left without a response, the frozen billing, and the trust that takes a hit. That’s why it’s worth thinking of this like fire insurance: you don’t buy it expecting the fire, you have it ready in case it comes.
The three defenses that actually work
The experience of those cities made clear that the basics, done well, are what save you. These are the three pillars of a realistic defense:
- Backups. Automatic, frequent copies of your information, stored in a place separate from your main system. The practical rule: at least one copy offline or in another location, one the attack can’t touch. A good backup turns a hijack into a simple “restore and carry on.”
- Patches and updates. Most attacks don’t use futuristic tricks: they exploit already-known flaws in systems no one updated. Keeping your operating system, your applications, and your server up to date closes the door most threats come through.
- Team training. Technology is no use if someone clicks where they shouldn’t. Teaching your people to recognize suspicious emails, not to reuse passwords, and to report anything odd is probably the cheapest and most profitable investment in security.
Why paying the ransom is almost never the way out
When the attack hits, the temptation is to pay and get back to normal fast. In practice it’s a bad bet: there’s no guarantee of recovering everything, you fund the attackers, and you mark yourself as a target willing to pay again. The organizations that came out best in 2019 were, for the most part, the ones that could restore from their backups and say no.
A well-made backup is what lets you refuse to pay and sleep easy.
That’s the difference between a weeks-long crisis and a few hours’ setback. And it doesn’t take magic: it takes order, consistency, and someone taking responsibility for verifying that the backups actually work.
Your defense plan in five steps
You don’t need to solve everything at once. Security is built like good custom software: you start with the essentials, measure, and grow over time. Start like this:
- Take a simple inventory. What information can’t you afford to lose? Customers, billing, records, history. That’s what has to be protected first.
- Turn on automatic backups and test them. A backup that was never restored is just a hope. Do a restore test at least once and put a date on the calendar to repeat it.
- Bring your systems up to date. Set a fixed day each month to install updates for machines, servers, and key applications.
- Reinforce passwords and access. Unique passwords, two-step verification where possible, and removing access from those who no longer need it.
- Train your team on the essentials. A brief talk about suspicious emails and good practices does more than any expensive padlock.
A ransomware attack doesn’t have to mean starting from scratch. At Normandia Web we help Mexican businesses set up backups, updates, and well-protected access, so an incident is a few hours’ setback and not a weeks-long crisis. The goal isn’t fear, it’s to keep operating calmly no matter what. If you want to review how protected your operation is today, let’s talk and design that first step together.
Ready to put it to work in your company?
Tell us what’s costing you time, money or control. We’ll help you figure out where to start.
Start your consultation →